Security Advisory

CVE-2016-10044

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-02-07 07:02:00
Last updated 2024-10-21 13:14:17
Assigner google_android
CVSS score not scored
State PUBLISHED

Description

The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup system call.